Multiple LDAP servers in a single profile - behavior

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Multiple LDAP servers in a single profile - behavior

L2 Linker

Dear comm,

 

when I have several LDAP servers in a profile for user authentication. How is this list utilized? Is only the first entry used? Are authentication requests distributed over all configured servers? How does it work?

 

Kind regards,

 

Rene

 

 

3 REPLIES 3

L6 Presenter

Hi,

 

l think this option is purely for redundancy. My guess is that AD servers are sharing the same user database:

 

https://live.paloaltonetworks.com/t5/Management-Articles/Using-More-than-Four-LDAP-Servers-in-a-Palo...

Dear Trancefor,

 

thank you for your answer. I am confused by this:

 

Usually four LDAP servers are more than enough to authenticate all the users in the domain, and to provide redundancy in case a LDAP server goes down.

 

This sounds like:"Hey, I will use one LDAP forever, if it goes down, I just will pick the next in the list".

 

Sometimes, larger companies have more than four LDAP servers with distributed environments in which users connect to dedicated LDAP servers. Users may contact LDAP servers that are not one of the four servers, and will try to authenticate to them.

 

So this sounds to me like (if the first statement above is true):"Hey I will use the first LDAP server of the first entry of the authentication sequence. If this authentication fails, I will contact the first LDAP server of the second entry of the authentication profile."

 

Bascially if you have two groups of LDAP servers:

 

Group1: 1,2,3,4

Group2:5,6,7,8

Authentication Sequence: Group1,Group2

 

Assuming no LDAP server goes down ever: LDAP1 will be contacted and LDAP5 might be contacted, the rest of the server will never be contacted. Am I right here?

 

Kind regards,


Rene

@Rboehme,

The servers in Group1 will be polled and contact will stop once a user is matched authenticated. If the entire Group1 does not find a match it will continue to Group2. If The first polling server in Group1 never goes down then I believe your assumption is correct that the others will never be consulted. 

  • 3479 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!